Senior Director, Information Security

Prompt Health

United States

Hybrid

USD 200,000 - 240,000

Full time

28 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote/hybrid environment
Competitive salaries
Equity potential

Job summary

Prompt Therapy Solutions, Inc in the United States seeks a Senior Director of Information Security to serve as HIPAA Security Officer and lead the security program.

You will own HIPAA/HITECH compliance, SOC 2 Type II, attestations, and policy framework, while partnering with Engineering, Legal and Privacy to translate risks into controls.

This hands-on leadership role builds and mature the security program, ensuring secure SDLC, third‑party risk, incident response, and ongoing governance.

Qualifications

  • 8+ years in information security, risk management or compliance with leadership
  • Deep practical HIPAA/HITECH healthcare security knowledge
  • Cloud security, IAM, vulnerability management, secure SDLC
  • Experience leading SOC 2 Type II or similar programs
  • Governance, policy framework, audit readiness experience
  • Knowledge of AI security, governance and risk management
  • Ability to translate technical issues into business impact

Responsibilities

  • Lead HIPAA Security Officer responsibilities and partner with Legal, Privacy, Compliance, and Engineering
  • Assess cloud architectures, CI/CD, IaC, IAM, and software supply-chain controls
  • Own HIPAA Security Rule compliance and risk management program
  • Own SOC 2 Type II program and audits, governance, remediation
  • Develop and govern information-security policy and control framework
  • Establish ownership for security controls and remediation tracking
  • Collaborate with Engineering, DevOps, IT to implement controls
  • Oversee vulnerability management and application security programs
  • Lead incident response framework and cross-functional coordination
  • Manage third-party risk management and security escalations
  • Govern emerging tech governance and data use with stakeholders
  • Ensure secure SDLC and software supply-chain controls
  • Monitor effectiveness of security controls and reporting

Skills

HIPAA/HITECH
Cloud security
SOC 2 Type II
AI security
Security governance
Executive communication
Third-party risk

Education

CISSP
CISM
CRISC
CISA
CHC

Job description

Job Title: Senior Director, Information Security

About Prompt

Prompt is revolutionizing healthcare by delivering highly automated and modern software to rehab therapy businesses, their teams, and the patients they serve. As one of the fastest-growing companies in healthcare SaaS and the new standard in healthcare technology, we are committed to building a team that thrives in our fast-paced, innovative environment.

As Prompt continues to scale, maintaining the trust of our customers, partners, and the patients they serve is critical. We are seeking a Senior Director, Information Security to serve as our HIPAA Security Officer and lead and mature our information security program as we continue to grow.

About The Role

The Senior Director, Information Security serves as the company’s designated HIPAA Security Officer and is accountable for leading and maturing the company’s information security program.

This role owns the governance, control environment, certification and audit programs, security risk management, policy framework, and cross-functional operating model required to maintain compliance with HIPAA/HITECH, SOC 2, and other applicable regulatory, contractual, and certification requirements.

The Senior Director will work closely with technical and business leaders to translate security requirements and risks into effective controls, clear ownership, and sustainable processes. This is a hands‑on leadership role for someone who wants to build and mature the program while leveraging strong technical resources across the organization.

Responsibilities
  • Serve as the company’s designated HIPAA Security Officer, leading the company’s information security program and partnering with Legal, Privacy, Compliance, Engineering, IT, and other stakeholders on related requirements.
  • Maintain sufficient technical depth sufficient technical depth to independently assess cloud architectures, application architectures, CI/CD pipelines, infrastructure-as-code, identity and access models, software supply-chain controls, and security monitoring approaches, while technical teams retain responsibility for detailed implementation and operations.
  • Own HIPAA Security Rule compliance, including the Security Risk Analysis, security risk-management plan, and ongoing oversight of required safeguards.
  • Own the company’s SOC 2 Type II program and other security certifications, attestations, and assurance programs, including control governance, audit readiness, evidence sufficiency, auditor relationships, identified deficiencies, remediation, and successful completion of audits and assessments.
  • Own the company’s information-security policy and control framework, including policy development, review, exceptions, ongoing governance, and alignment with applicable regulatory, contractual, and business requirements.
  • Establish clear ownership for security controls across the organization and ensure deficiencies, vulnerabilities, risks, and remediation plans are identified, prioritized, tracked, validated, and appropriately escalated.
  • Partner with Engineering, DevOps, architecture, and IT leaders to evaluate security approaches and ensure technical controls appropriately address identified requirements, while technical teams retain responsibility for detailed design and implementation.
  • Establish and oversee the company’s vulnerability-management and application-security programs, including expectations for vulnerability identification, penetration testing, secure software development practices, security testing, remediation, exceptions, and escalation.
  • Own the security incident-response framework and coordinate the company’s response to security incidents, partnering with technical teams on investigation and remediation and with Legal, Privacy, Compliance, and executive leadership on broader incident assessment and response.
  • Lead the security aspects of third‑party risk management, enterprise customer diligence, audits, RFPs/RFIs, and security escalations.
  • Partner with Product, AI, Engineering, Legal, and other stakeholders to establish appropriate governance for emerging technologies and the use of sensitive data.
  • Establish and oversee secure SDLC and software supply‑chain requirements, including source‑control protections, CI/CD security, dependency and container security, infrastructure‑as‑code security, secrets management, security testing, artifact integrity, release controls, vulnerability remediation, and risk‑based security gates.
  • Maintain appropriate visibility into the effectiveness of the company’s security controls and partner with responsible technical owners to evaluate areas including access controls, data protection, cloud and application security, logging, monitoring, and business continuity.
  • Oversee the effectiveness of the company’s security controls and provide executive leadership with appropriate visibility into significant risks, remediation progress, and emerging security concerns.
  • Continuously improve the company’s information‑security operating model so that requirements are clear, ownership is durable, and controls operate effectively in practice.
Qualifications
  • 8+ years of experience in information security, risk management, compliance, or related disciplines, including meaningful leadership responsibility.
  • Deep practical knowledge of HIPAA/HITECH and healthcare security and compliance requirements, ideally within a covered entity or business associate environment.
  • Strong working knowledge of cloud security, application security, IAM, vulnerability management, endpoint security, secure SDLC practices, and modern SaaS architecture.
  • Demonstrated experience leading SOC 2 Type II or comparable certification and assurance programs.
  • Experience building or materially improving information security governance, control environments, policy frameworks, audit readiness, and cross-functional accountability.
  • Strong working knowledge of AI security, governance, and risk management, including risks associated with sensitive data and emerging AI technologies.
  • Ability to engage credibly with technical leaders, evaluate proposed approaches, identify material risk, and translate technical issues into business, compliance, and customer impact.
  • Strong executive judgment and communication skills, with the ability to work effectively across Legal, Engineering, Product, IT, AI, People, Finance, auditors, customers, and executive leadership.
  • Demonstrated ability to drive accountability across functions without relying solely on direct reporting relationships.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CHC, or similar are preferred but not required where equivalent experience is demonstrated.
Why Work for Prompt?
  • Big Challenges: Here at Prompt, we are solving complex and unique problems that have plagued the healthcare industry since the dawn of time.
  • Talented People: Prompt didn't happen by chance, it's a team of incredibly talented and proven individuals who all made their mark before joining forces to build the greatest software on the planet for rehab therapists.
  • Healthy Approach: This isn't an investment bank. At Prompt you own your workload and the entire organization takes a liking to smart work (over hard work).
  • Positive Impact: Prompt helps outpatient rehab organizations treat more patients and deliver better care with less environmental waste. That means less surgery and less narcotic‑based pain treatment, all while turning a paper‑heavy industry digital.
Perks – What You Can Expect
  • Competitive salaries
  • Remote/hybrid environment
  • Potential equity compensation for outstanding performance
  • Flexible PTO
  • Company‑wide sponsored lunches
  • Company paid disability and life insurance benefits
  • Company paid family and medical leave
  • Medical, dental, and vision insurance benefits
  • Discounted pet insurance
  • FSA/DCA and commuter benefits
  • 401k
  • Credits for online fitness classes/gym memberships
  • Recovery suite at HQ — includes a cold plunge, sauna, and shower

Here at Prompt, we are committed to fostering a fair and respectful work environment. As part of this commitment, it is our policy not to hire individuals from Prompt Customers unless they have obtained their current employer's explicit consent. We believe in upholding strong professional relationships and respecting the agreements and commitments our customers have with their employees. We appreciate your understanding and cooperation regarding this policy. If you have any questions or concerns, please don't hesitate to reach out to our People Department.

Prompt Therapy Solutions, Inc is an equal opportunity employer, indiscriminate of race, color, religion, ethnicity, ancestry, national origin, sex, gender, gender identity, sexual orientation, age, marital status, veteran status, disability, medical condition, or any other protected characteristic. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Prompt Therapy Solutions, Inc is an E-Verify Employer.

Here at Prompt, we are committed to fostering a fair and respectful work environment. As part of this commitment, it is our policy not to hire individuals from Prompt Customers unless they have obtained their current employer's explicit consent. We believe in upholding strong professional relationships and respecting the agreements and commitments our customers have with their employees. We appreciate your understanding and cooperation regarding this policy. If you have any questions or concerns, please don't hesitate to reach out to our People Department.

Prompt Therapy Solutions, Inc is an equal opportunity employer, indiscriminate of race, color, religion, ethnicity, ancestry, national origin, sex, gender, gender identity, sexual orientation, age, marital status, veteran status, disability, medical condition, or any other protected characteristic. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Prompt Therapy Solutions, Inc is an E-Verify Employer.

Compensation Range: $200K - $240K

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Director, Security & Compliance
Senior Director, Security & Compliance

Prompt Health • United States

Hybrid
USD 180,000 - 240,000
Competitive salaries
Remote/hybrid environment
Potential equity compensation for outs
+10
Senior Director, Information Security
Senior Director, Information Security

LaunchTN • United States

Hybrid
USD 180,000 - 250,000
Remote/hybrid environment
Equity compensation (potential)
Flexible PTO
+2
Senior Director, Security & Compliance
Senior Director, Security & Compliance

Prompt • United States

On-site
USD 180,000 - 280,000
Competitive salaries
Remote/hybrid environment
Equity potential
+10
Program Lead, Executive Operations
Program Lead, Executive Operations

Prompt Health • United States

Hybrid
USD 115,000 - 130,000
Competitive salaries
Remote/hybrid environment
Potential equity compensation
+10
Program Lead, Executive Operations
Program Lead, Executive Operations

Prompt • United States

On-site
USD 120,000 - 190,000
Remote/hybrid environment
Competitive salaries
401k
+3
Program Lead, Executive Operations
Program Lead, Executive Operations

Launch Tennessee • United States

On-site
USD 130,000 - 190,000
Competitive salaries
Remote/hybrid environment
Equity potential
+2
Senior Full Stack Engineer - Data & Analytics
Senior Full Stack Engineer - Data & Analytics

Prompt • United States

On-site
USD 140,000 - 190,000
Remote/hybrid environment
Competitive salaries
Equity opportunities
+3
Senior Full Stack Engineer - Data & Analytics
Senior Full Stack Engineer - Data & Analytics

Launch Tennessee • United States

On-site
USD 90,000 - 130,000
Competitive salaries
Remote/hybrid environment
Flexible PTO
+2
Senior Full Stack Engineer - Data & Analytics
Senior Full Stack Engineer - Data & Analytics

Prompt Health • United States

On-site
USD 110,000 - 150,000
Competitive salaries
Remote/hybrid environment
Equity compensation
+6
Staff Software Engineer
Staff Software Engineer

Vuejobs • Northern (KY)

Hybrid
USD 140,000 - 175,000
Competitive salaries
Remote/hybrid environment
Potential equity compensation for outs
+9